Insights

2026-08-26 · Article

Three Laws. Three Exclusions. One You Actually Owe.

The three US chatbot statutes everyone cites all exclude customer service. The obligation that does apply arrived on 2 August 2026 and is discharged by one sentence at the start of the call.

By Frans Vermaak

Three Laws. Three Exclusions. One You Actually Owe.

On 2 August 2026, Article 50(1) of the EU AI Act became applicable. Not under consultation. Not entering a grace period. Applicable. Any AI system conducting a genuine two-way exchange with a natural person must inform that person they are talking to a machine, unless it is obvious from the circumstances. The obligation is live, has been live for three weeks, and carries a penalty ceiling of 15 million euro or 3 per cent of total worldwide turnover.

In the same period, we read the US state chatbot statutes most often appearing in contact-centre compliance discussion: California SB 243, Washington HB 2225 and Nebraska LB 525.

All three exclude customer service.

Two of them are not in force until 2027.

This is the fourth piece in The Deflection Gap. The first found that callers ask for a human within three minutes of being connected to an AI agent. The second followed a bank that cut 45 customer service roles on a projection nobody had checked against what was happening on its own call floor, and found that research warning of exactly that error had been published three months earlier. The third found that nobody agrees on what a resolved contact is, which means the deflection figures have no fixed denominator. This one finds that nothing in the instruments we surveyed requires you to give a caller a way out.

Reading statutes is tedious work. The definitions sections run long, the exclusions are cross-referenced across subsections, and what a bill says in its title and what it covers in its operative provisions can be entirely different things. This is not a criticism of how compliance conversations proceed; it is a description of how they proceed. It also explains how an industry winds up managing risk against obligations that do not apply to it, while the one that does became applicable three weeks before this article was published.


Article 50 and what it actually requires

The four conditions for Article 50(1) are cumulative. Drawn from the European Commission's published FAQ: it must be an AI system; there must be a genuine two-way exchange rather than merely automated responses; the interaction must be direct, meaning the AI communicates with the person rather than through an intermediary; and the person must be a natural person. A conversational agent handling inbound calls meets all four. The obligation is to inform the caller, at the latest at the time of the first interaction, that they are dealing with an AI system.

The European Commission published draft transparency guidelines on 8 May 2026 and closed the consultation on 3 June 2026. Those guidelines remain in draft. The four conditions come from the published FAQ, not from them.

There is no grace period for Article 50(1). The grace period in the Act applies only to the Article 50(2) obligation: the marking and detection requirements for AI-generated content, only for systems placed on the market before 2 August 2026, running to 2 December 2026. Content generated before that date needs no retrospective labelling. None of that touches the conversational-disclosure requirement. Article 50(1) has applied since 2 August 2026.

The regulation applies independently of risk classification. An organisation with no high-risk AI system still carries the Article 50(1) obligation the moment it operates a conversational agent in scope. The question is not what tier your system is in. It is whether a natural person is on the other end of a genuine two-way exchange.

For a South African BPO, the operative question is not where the delivery centre is. It is where the caller is. A Johannesburg contact centre handling inbound calls for a European banking or insurance client is serving EU users. Whether Article 50(1) applies depends on the profile of those clients' customers, not on where the people answering are sitting. For BPOs with European-facing client books, the Article 50 question belongs in the service agreement, not in a separate compliance workstream at some future point. The obligation is live now, for the clients, and they are the ones facing the penalty ceiling.


Three statutes, three exclusions

California SB 243 covers companion chatbots: AI systems with a natural language interface capable of meeting a user's social needs, exhibiting anthropomorphic features and sustaining a relationship across multiple interactions. The customer service exclusion is explicit. A bot used only for customer service, a business's operational purposes, productivity and analysis, internal research or technical assistance sits outside the definition. The word "only" carries structural weight; a system that sustains an emotionally responsive relationship across calls could argue back into scope. A standard service agent does not. SB 243 has been in effect since 1 January 2026. It is in force. It does not reach ordinary customer service.

Washington HB 2225 was signed on 24 March 2026. It does not become effective until 1 January 2027. It excludes customer service unless a system both sustains a relationship across multiple interactions and generates outputs likely to elicit emotional responses: a conjunctive test requiring both limbs. It also defines a user as a natural person interacting for personal use, placing business-to-business deployments outside it. Among the things it does require is that operators prevent a covered chatbot from claiming to be human. It is not in force, and it does not cover ordinary customer service.

Nebraska LB 525, the Conversational Artificial Intelligence Safety Act, was signed on 14 April 2026. Its operative sections do not take effect until 1 July 2027. It excludes applications primarily designed and marketed for commercial use by business entities and those confined to narrow and discrete topics. Enforcement is by the Attorney General only, with civil penalties from 1,000 dollars per violation to a ceiling of 500,000 dollars per operator per action, and no private right of action. Idaho SB 1297 follows the Nebraska model with the same commencement date.

These are the statutes we saw cited. Four instruments. All four exclude customer service. Three do not commence until 2027. We are not characterising the general state of compliance discussion; we are describing what we read.


The two that do reach a contact centre

Two US statutes apply to ordinary customer interactions.

Maine's Act to Ensure Transparency in Consumer Transactions Involving Artificial Intelligence has been in force since 16 September 2025. It is proactive: where a deployment could mislead a reasonable consumer into believing they are dealing with a person, clear and conspicuous notification is required, before anyone asks. The definition of an AI chatbot expressly covers aural communication, which matters for voice deployments. Guidance on outbound calling places the disclosure at the start of the call. The enforcement route is the Maine Unfair Trade Practices Act, with AG civil penalties up to 1,000 dollars per violation and a consumer's own action where they can show financial harm.

Utah's Artificial Intelligence Policy Act, as narrowed by SB 226 effective 7 May 2025, is reactive: in a consumer transaction, a supplier using generative AI must disclose it when a consumer clearly and unambiguously asks. Proactive disclosure survives for high-risk interactions in regulated occupations, covering contexts such as financial, legal, medical and mental health. A safe harbour applies to suppliers who disclose clearly and conspicuously at the outset. Administrative fines run to 2,500 dollars and civil penalties to 5,000 dollars per violation. SB 332 extended the Act's expiry to July 2027.

Maine says tell them before they ask. Utah says tell them when they ask. Article 50 says tell them at the start of the first interaction. One sentence at the top of the call satisfies all three.


What compliance actually looks like

Identify which deployments conduct a genuine two-way exchange with a natural person. Establish whether any of those people are in the EU, which for a BPO is a question about the client's customers rather than your own. Put the disclosure in the opening turn, not in a recorded preamble nobody hears. Log it so it can be evidenced. Make sure the system does not deny being a machine when asked, because active deception is what every one of these regimes punishes, including all three that otherwise exclude customer service.

Neither the UK nor South Africa has an equivalent disclosure statute. South Africa has the Protection of Personal Information Act 4 of 2013; POPIA governs how personal information is processed but does not impose an AI-disclosure obligation in this form. The FCA's Consumer Duty, alongside FG21/1 on fair treatment of customers in vulnerable circumstances (updated July 2026), is outcome-based: a system producing worse outcomes for vulnerable customers fails the Duty regardless of what the averages show. Section 166 skilled-persons reviews are the supervisory instrument. Ofcom separately requires telecoms providers to have policies ensuring vulnerable customers are treated fairly. None of that says you must announce the machine. All of it makes the absence of an announcement harder to explain once something has gone wrong for somebody who could not tell.

This is not legal advice. It is a reading of published statutes, given so that you can ask your own counsel a sharper question than "are we affected".


The close

Four articles. People want the exit and reach for it within three minutes. At least one bank cut 45 roles on a business case that did not survive contact with its own call volumes. The measure used to justify the deployment has no agreed definition. And nothing in the instruments surveyed here, across two continents and nine jurisdictions, requires anyone to provide a human.

The exit is a design choice. The customer experience it produces is a design choice. The outcomes it generates, for the callers who cannot get through it and for the ones who simply stop calling, are design choices too. The instruments that do apply say: tell them they are talking to a machine. They do not say: give them a way out.

Nobody is going to make you fix this. That is precisely the point.

The artefact

Disclosure Obligations Matrix: nine jurisdictions, what triggers disclosure, and the enforcement ceiling

Artefact: Disclosure Obligations Matrix, one page: jurisdiction, instrument, in force from, whether it reaches ordinary customer service, and the enforcement ceiling.

Sources

Claim Source Checked
Article 50 applicable from 2 August 2026; the 50(2) marking grace period runs to 2 December 2026; no grace period for 50(1); no retrospective labelling European Commission, Transparency obligations under Article 50 AI Act FAQ, digital-strategy.ec.europa.eu 2026-08-04
The four cumulative conditions for Article 50(1); notice at first interaction Commission FAQ; Commission transparency guidelines, draft published 8 May 2026 2026-08-04
Penalty ceiling of 15 million euro or 3 per cent of worldwide turnover; applies independently of high-risk classification; non-EU businesses serving EU users in scope Regulation (EU) 2024/1689 Article 50 and Commission guidance 2026-08-04
California SB 243 companion-chatbot definition and the customer service exclusion; effective 1 January 2026; annual reporting from 1 July 2027; private right of action, greater of actual damages or 1,000 dollars per violation SB 243 bill text, leginfo.legislature.ca.gov (2025 to 2026 session) 2026-08-07
Washington HB 2225 signed 24 March 2026, effective 1 January 2027; conjunctive customer service exclusion; user defined as a natural person for personal use; operators must stop a covered chatbot claiming to be human HB 2225 bill text, lawfilesext.leg.wa.gov; Mayer Brown and Troutman analyses 2026-08-07
Nebraska LB 525 signed 14 April 2026, sections 12 to 18 operative 1 July 2027; commercial and narrow-topic exclusions; AG-only enforcement, 1,000 dollars per violation to a 500,000 dollar cap, no private right of action LB 525 slip law, nebraskalegislature.gov 2026-08-07
Idaho SB 1297 follows the Nebraska model, effective 1 July 2027 Orrick, 2026 State Chatbot Laws, April 2026 2026-08-07
Maine Act signed 12 June 2025, effective 16 September 2025; proactive deception standard; definition covers aural communication; outbound audio disclosure at the start; UTPA breach, up to 1,000 dollars per violation, consumer action on financial harm Maine Revised Statutes Title 10, legislature.maine.gov; DataGuidance and CompliancePoint summaries 2026-08-07
Utah SB 226 effective 7 May 2025 narrowing disclosure to clear and unambiguous requests; high-risk regulated-occupation carve-in; safe harbour; fines up to 2,500 and 5,000 dollars; SB 332 extends expiry to July 2027 Davis Wright Tremaine and Davis Polk analyses of SB 226 and SB 332; Utah AIPA 2026-08-07
South Africa has no equivalent AI-disclosure statute; POPIA governs the processing of personal information Protection of Personal Information Act 4 of 2013 (South Africa) 2026-08-04
Findings of articles 1 to 3 of this series, as summarised here Tech Sight, The Deflection Gap, articles 1 to 3, each carrying its own sources table 2026-08-25
FCA Consumer Duty and FG21/1, updated July 2026; section 166 skilled-persons reviews; Ofcom vulnerable-customer requirements FCA and Ofcom published guidance 2026-08-04

Where we relied on secondary sources. The Idaho position, and the procedural detail on the Washington and Utah amendments, reach us through law-firm analyses rather than our own reading of every section. The California, Washington, Nebraska and Maine primary texts we read directly. Where the two disagree, believe the statute.

A correction to our own material. The planning note for this series characterised the US state chatbot laws as imposing a disclosure duty on contact centres. That was wrong, and this article is the correction.

This is not legal advice. It is a reading of published statutes, given so that you can ask your own counsel a sharper question than "are we affected".

Interests declared. The law firms cited publish client-facing analysis to attract instructions. And ours, plainly, because this series asks you to check who paid for every number you are shown. Tech Sight advises buyers on contact-centre automation, including on the disclosure design discussed here. We also sell in this market: agentic AI for document understanding and document intelligence, and intelligent chatbots; and we hold an equity interest in Kobliat, an intelligent contact-centre platform owned by a separate company. We therefore have a direct commercial interest in you taking this question seriously, and you should read the article with that in mind. Every statute cited is named with its section and commencement date so that you can check us rather than trust us.

Correction policy: if we have misread a section, tell us and this article will carry the correction and the citation at the top.

Book an AI Audit

More from Insights

People Will Take the Bot. They Cannot Find the Door.

2026-08-26

The 45 Jobs That Were Not Redundant

2026-08-26

Nobody Published the Denominator

2026-08-26